將機器設定為預期狀態

注意

Azure Automation State Configuration將於2027年9月30日退役,請於該日期前轉換為Azure機器配置。 欲了解更多資訊,請參閱blog文章公告。 Azure機器組態服務結合了 DSC 擴充功能、Azure Automation State Configuration 以及客戶反饋中最常被要求的功能。 Azure機器配置也包含透過支援 Arc 的伺服器 支援混合機器。

重要

2025 年 3 月 31 日,入口網站將會移除 [新增]、[撰寫組態] 和 [資源庫] 導覽連結。

警告

Azure Automation DSC for Linux 已於 2023 年 9 月 30 日正式退休。 如需詳細資訊,請參閱公告。

Azure Automation State Configuration 讓你能為伺服器指定設定,並確保這些伺服器隨時間保持在指定狀態。

  • 將虛擬機器加入 Azure Automation DSC 進行管理
  • 將配置上傳至 Azure Automation
  • 將設定編譯成節點設定
  • 將節點設定指派給受控節點
  • 檢查受控節點的合規性狀態

針對此教學課程,我們會使用簡單的 DSC 設定,以確保在 VM 上安裝 IIS。

必要條件

注意

Windows Server 2008 與 Windows Server 2008 R2 已達到支援終止(EOS)。 欲了解更多資訊,請參閱Windows Server 2008 和 Windows Server 2008 R2 支援終止及執行原地升級至 Windows Server 2016、2019、2022 或 2025。 檢視你的使用情況,並相應規劃作業系統升級與遷移。

對部分設定的支援

Azure Automation State Configuration 支援使用 部分配置。 在此情境下,DSC 會被設定為獨立管理多個設定,每個設定都從 Azure Automation 取得。 不過,每個自動化帳戶只能指派一項設定檔給一個節點。 這表示如果您要針對節點使用兩個組態,則需要兩個自動化帳戶。

如需有關如何從提取服務註冊部分組態的詳細資料,請參閱部分組態的文件。

如需團隊如何合作以協同管理伺服器,並將設定當作程式碼使用的詳細資訊,請參閱了解 DSC 在 CI/CD 管線中的角色。

登入 Azure

請使用 Connect-AzAccount 指令登入您的Azure訂閱,並依照螢幕指示操作。

Connect-AzAccount

建立並上傳配置到 Azure Automation

在文字編輯器中輸入下列項目,並將其於本機儲存為 TestConfig.ps1。

configuration TestConfig {
   Node WebServer {
      WindowsFeature IIS {
         Ensure               = 'Present'
         Name                 = 'Web-Server'
         IncludeAllSubFeature = $true
      }
   }
}

注意

Azure Automation 中的設定名稱必須限制在不超過 100 個字元。

在需要匯入多個模組以提供 DSC 資源的更進階案例中,請確定每個模組在設定中都有唯一的 Import-DscResource 行。

呼叫 Import-AzAutomationDscConfiguration Cmdlet,以將設定上傳至自動化帳戶中。

$importAzAutomationDscConfigurationSplat = @{
    SourcePath = 'C:\DscConfigs\TestConfig.ps1'
    ResourceGroupName = 'MyResourceGroup'
    AutomationAccountName = 'myAutomationAccount'
    Published = $true
}
Import-AzAutomationDscConfiguration @importAzAutomationDscConfigurationSplat

將設定編譯成節點設定

DSC 設定必須編譯成節點設定,才可以指派至節點。 請參閱 DSC 設定。

呼叫 Start-AzAutomationDscCompilationJob Cmdlet,以將 TestConfig 設定編譯成自動化帳戶中名為 TestConfig.WebServer 的節點設定。

$startAzAutomationDscCompilationJobSplat = @{
    ConfigurationName = 'TestConfig'
    ResourceGroupName = 'MyResourceGroup'
    AutomationAccountName = 'myAutomationAccount'
}
Start-AzAutomationDscCompilationJob @startAzAutomationDscCompilationJobSplat

註冊一個由 State Configuration 管理的虛擬機

你可以用 Azure Automation State Configuration 管理Azure虛擬機(包括經典版和 Resource Manager)、本地虛擬機、Linux 機器、AWS 虛擬機以及本地實體機器。 本文將介紹如何僅註冊 Azure Resource Manager 虛擬機。 關於註冊其他類型機器的資訊,請參閱透過 Azure Automation State Configuration 進行管理之機器的加入程序。

呼叫 Register-AzAutomationDscNode cmdlet,將你的虛擬機Azure Automation State Configuration註冊為管理節點。

$registerAzAutomationDscNodeSplat = @{
    ResourceGroupName = 'MyResourceGroup'
    AutomationAccountName = 'myAutomationAccount'
    AzureVMName = 'DscVm'
}
Register-AzAutomationDscNode @registerAzAutomationDscNodeSplat

指定設定模式設定

使用 Register-AzAutomationDscNode Cmdlet,以將 VM 註冊為受控節點,並指定設定屬性。 例如,您可藉由指定 ApplyOnly 作為 ConfigurationMode 屬性的值,以指定讓電腦的狀態只套用一次。 State Configuration 在初次檢查後不會嘗試套用該組態。

$registerAzAutomationDscNodeSplat = @{
    ResourceGroupName = 'MyResourceGroup'
    AutomationAccountName = 'myAutomationAccount'
    AzureVMName = 'DscVm'
    ConfigurationMode = 'ApplyOnly'
}
Register-AzAutomationDscNode @registerAzAutomationDscNodeSplat```

You can also specify how often DSC checks the configuration state by using the
`ConfigurationModeFrequencyMins` property. For more information about DSC configuration settings,
see [Configuring the Local Configuration Manager][05].

```powershell
# Run a DSC check every 60 minutes
$registerAzAutomationDscNodeSplat = @{
    ResourceGroupName = 'MyResourceGroup'
    AutomationAccountName = 'myAutomationAccount'
    AzureVMName = 'DscVm'
    ConfigurationModeFrequencyMins = 60
}
Register-AzAutomationDscNode @registerAzAutomationDscNodeSplat```

## Assign a node configuration to a managed node

Now we can assign the compiled node configuration to the VM we want to configure.

```powershell
# Get the ID of the DSC node
$getAzAutomationDscNodeSplat = @{
    ResourceGroupName = 'MyResourceGroup'
    AutomationAccountName = 'myAutomationAccount'
    Name = 'DscVm'
}
$node = Get-AzAutomationDscNode @getAzAutomationDscNodeSplat

# Assign the node configuration to the DSC node
$setAzAutomationDscNodeSplat = @{
    ResourceGroupName = 'MyResourceGroup'
    AutomationAccountName = 'myAutomationAccount'
    NodeConfigurationName = 'TestConfig.WebServer'
    NodeId = $node.Id
}
Set-AzAutomationDscNode @setAzAutomationDscNodeSplat

此動作會將名為 TestConfig.WebServer 的節點設定,指派至已註冊的 DSC 節點 DscVm。 根據預設,DSC 節點會每隔 30 分鐘檢查節點設定的合規性。 關於如何更改合規檢查間隔的資訊,請參見 Configuring the Local Configuration Manager。

檢查受控節點的合規性狀態

您可使用 Get-AzAutomationDscNodeReport Cmdlet,以取得受控節點合規性狀態的報告。

# Get the ID of the DSC node
$getAzAutomationDscNodeSplat = @{
    ResourceGroupName = 'MyResourceGroup'
    AutomationAccountName = 'myAutomationAccount'
    Name = 'DscVm'
}
$node = Get-AzAutomationDscNode @getAzAutomationDscNodeSplat

# Get an array of status reports for the DSC node
$getAzAutomationDscNodeReportSplat = @{
    ResourceGroupName = 'MyResourceGroup'
    AutomationAccountName = 'myAutomationAccount'
    NodeId = $node.Id
}
$reports = Get-AzAutomationDscNodeReport @getAzAutomationDscNodeReportSplat

# Display the most recent report
$reports[0]

下一步